Common signs include recertifications with no remediation follow-through, exceptions that never expire, unclear approvers and audit evidence assembled manually after the fact. Those symptoms show the process is reporting on control activity rather than governing the control itself.
When access governance stops changing access
The clearest sign is that the process produces artefacts, not decisions. Reviews are completed on schedule, but access rarely changes, exceptions linger, and nobody can point to a policy owner who is accountable for outcomes. At that point, access governance is functioning as evidence collection, not control enforcement.
A second warning is that the programme has lost operational feedback. If approvers are unclear, remediation tickets are not tracked to closure, and recertification results do not feed role design or removal of toxic access, the control may still pass an audit while failing to govern actual entitlement risk.
For teams working across IAM and identity governance, the practical test is whether review findings change the population of accounts, entitlements, and exceptions after the cycle ends.
Why manual evidence and permanent exceptions are red flags
Manual evidence assembly often means the process is optimised for inspection day rather than continuous control. If screenshots, spreadsheets, and after-the-fact sign-offs are needed to prove a review happened, the organisation is probably preserving records instead of managing access risk in real time.
Exceptions that never expire are just as telling. A legitimate temporary exception should have an owner, a rationale, a review date, and a defined end state. When exceptions become standing permissions, the governance model has shifted from exception handling to permission retention.
That pattern is especially visible where teams have not connected review workflows to access reviews and certification outcomes that actually remove access, and where lifecycle cleanup is weak.
Strong programmes also keep role and lifecycle hygiene in view. Joiner-mover-leaver handling should remove access when people change roles or leave, otherwise recertification becomes a thin layer over accumulating privilege.
How to tell the difference between auditable and governing
Access governance is only a compliance exercise when the evidence is complete but the control effect is weak. A mature programme can show who approved what, why access existed, what was removed, and how recurring exceptions changed the access model. A compliance-only programme can usually show only that a review occurred.
One useful discriminator is whether the review process informs upstream design. If repeated exceptions, SoD conflicts, or access reviews never trigger role redesign, ownership cleanup, or policy changes, the organisation is treating each cycle as a reporting event rather than a governance mechanism.
Good programmes also tie review activity to entitlements and role structure, which is why IAM and IGA basics matter: governance only works when provisioning, review, and revocation are part of the same control loop.
Risk and Threat Considerations
When access governance becomes ceremonial, excess privilege tends to persist unnoticed. That creates a wider attack surface, longer dwell time for compromised accounts, and more opportunities for lateral movement through stale, overassigned, or unowned access.
Failure mechanism: Reviews are completed without meaningful remediation, so elevated access survives across cycles and exceptions never age out. That leaves the organisation with apparent control coverage but no durable reduction in standing privilege.
Impact: A compromised account, vendor connection, or internal user can retain more reach than the business intended, increasing the likelihood of unauthorized access, segregation-of-duties failures, and audit findings that reflect real exposure rather than paperwork gaps.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Overprivilege is the core sign of weak access governance here. |
| NHI-01 — Improper Offboarding | Stale access after role change or exit shows governance is not closing the loop. | |
| NHI-07 — Long-Lived Secrets | Permanent exceptions often behave like long-lived access that never expires. | |
| Recommendation — Reduce standing privilege and remove access that reviews cannot justify. Revoke access promptly when ownership or employment status changes. Set expiry and rotation expectations for any access that is granted temporarily. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Account lifecycle control underpins whether access reviews actually change entitlements. |
| AC-6 — Least Privilege | Recurring excess access means least privilege is not being enforced operationally. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Manual evidence and weak follow-through show audit activity without effective control action. | |
| Recommendation — Tie reviews to account removal, disablement, or reclassification decisions. Trim entitlements to the minimum required for the current business need. Use audit outputs to trigger remediation, not just to satisfy review. | ||
| CIS Controls v8 | CIS-5 — Account Management | Access governance failures are visible in account lifecycle drift and stale entitlements. |
| Recommendation — Continuously remove stale access and validate account ownership. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control governance is the exact management problem being assessed. |
| A.8.2 — Privileged access rights | Persistent exceptions and overbroad access are most dangerous for privileged rights. | |
| Recommendation — Define and operate access rules so approvals lead to enforced changes. Review privileged access more frequently and remove unjustified standing rights. | ||
Practitioner Guidance
What to verify: Confirm that every recertification cycle has a closure path, meaning rejected or expired access is removed, not merely recorded. If the review output cannot be traced to a revocation, role change, or exception expiry, the control is not governing access.
What to prioritise: Focus first on high-risk populations, such as privileged users, shared accounts, and access with business-critical system reach. That is where compliance theatre turns into material exposure fastest.
What good looks like: Owners are unambiguous, exceptions have end dates, remediation is measurable, and recurring review findings feed role cleanup or policy change. The programme should reduce entitlement noise over time, not just preserve audit history.
Practitioner takeaway: The simplest test is whether the process makes future access safer. If each cycle leaves the same exceptions, the same overprivilege, and the same manual evidence trail, you have a reporting process, not access governance.
Related resources from NHI Mgmt Group
- What is the difference between role-based access and API key governance for NHI security?
- When does access compliance become a governance control instead of a reporting exercise?
- What are the signs that access governance is too weak for HIPAA and meaningful use compliance?
- How should security teams govern non-human identities for compliance?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org